Myanmar: Note on New Draft Cyber Security Law • Very significant powers, including regulatory powers over freedom of expression and the power to impose sanctions, are allocated to bodies such as the Central and Steering Committees which are not independent of the military regime, the exercise of those powers is not subject to appropriate either procedural or substantive constraints, and the decisions of those bodies are not subject to court review. • Broad-ranging and vaguely-worded restrictions on the content of what may be disseminated online are imposed (and applied by the bodies noted above). • A number of other (i.e. beyond content) criminal offences are created which are again vague, are repetitive with only minor linguistic differences between provisions, and lack the appropriate (and specific) intent requirements that would be needed to justify such prohibitions. • A number of onerous obligations are imposed on digital service providers, defined very broadly, as well as sub-sets of that broad category (such as “cyber security service providers”), some of which are clearly designed to further military control of digital communications, some of which are unreasonably burdensome for service providers and many of which simply fail to take into account the working reality of international service providers. • The scope of special obligations ostensibly designed to protect critical information infrastructure is far too broad both in terms of the way that infrastructure is defined and the bodies which may be deemed to be subject to these rules. Our February 2021 Analysis also included a critique of the rules in the February 2021 version of the draft Law on personal data protection. These rules have been retained, essentially verbatim, in the current version of the draft Law. We note that these rules are already part of the current legal framework of Myanmar as they were included, again essentially verbatim, in the amendments to the Electronic Transactions Act (ETA) which were introduced in February 2021.4 While the current draft of the Cyber Security Law would repeal the ETA, it remains the case that this is a fundamentally limited set of protective rules on personal data protection, while other rules in the draft Law require this data to be stored locally and to be retained for “up to three years” (which we understand as meaning for three years), both of which are not legitimate under international law, as well as to be shared with an “assigned person or authorised organisation requested under any existing law”, without adequate protections for this being put in place. Those amendments were introduced around the same time as the February 2021 draft Cyber Security Law was withdrawn and were drawn directly from that draft Law. 4 The Centre for Law and Democracy is a non-profit human rights organisation working internationally to provide legal expertise on foundational rights for democracy. 2

Select target paragraph3